
DFIR-LABS
Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Malware Configuration And Payload Extraction

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Distributed & real time digital forensics at the speed of the cloud

JA4+ is a suite of network fingerprinting standards

Collection of forensic tools

Malcom - Malware Communications Analyzer

Behavioral Malware Analysis of a Simulated Multi-Stage Windows Malware Sample using FLARE-VM and REMnux. Evidence-driven DFIR investigation with IOC…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

A tool to assist with network-based hunting for GRU's Drovorub malware c2

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis

Malware samples, analysis exercises and other interesting resources.

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…